---
title: "MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding"
description: "CVE-2026-59971 (CVSS 10.0): mysql-mcp-server SSE mode skipped Host/Origin DNS-rebinding protection, bound 0.0.0.0 with no auth - unauthenticated SQL until 0.4.2."
url: "https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/"
source: html
---

On this page

- What broke
- Fix and residual risk
- How Anomity surfaces exposed MCP HTTP
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding

![Anomity robot illustrating MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding]

Advisory Critical

# MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding

Anomity Research
Anomity Threat Research
·
Sep 21, 2026
·
3 min read

Share: Copied

MCP Server Security · Critical · CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2) · Sep 21, 2026

Affected mysql-mcp-server (PyPI) before 0.4.2 when MCP_TRANSPORT=sse; default stdio transport is not affected

**CVE-2026-59971** (**GHSA-rqfv-2mw9-78g2**) is a critical flaw in **mysql-mcp-server**, the popular PyPI MCP package that fronted MySQL for coding agents. In **SSE/HTTP** mode the server skipped the SDK's Host/Origin DNS-rebinding guards, listened broadly, and required no authentication - so unauthenticated callers could drive SQL. Fixed in **0.4.2**; GHSA published **11 September 2026**. CVSS **10.0**.

## What broke

Trigger condition: **MCP_TRANSPORT=sse**. In that mode the package constructed **SseServerTransport without passing security_settings**. The MCP Python SDK's DNS-rebinding protection - Origin and Host validation - therefore stayed disabled. The Starlette app also lacked **CORS** and **TrustedHost** middleware, bound **0.0.0.0 by default**, and exposed routes **without authentication**.

That combination is the classic local-MCP HTTP failure mode: developers assume "it is just on my laptop," while the browser origin boundary and the network bind disagree. DNS rebinding lets a malicious page reach a listener the developer thought was private; a directly exposed host needs no rebinding at all. Either path yields **unauthenticated SQL** against whatever database credentials the MCP process holds. Coding-agent servers share the assumption; [OpenCode's cross-site upgrade flaw](https://anomity.ai/blog/opencode-cross-site-upgrade-rce-ghsa-632h-h47v-g4x4/) reached a local server through a form post instead.

Default **stdio** is not affected. The CVE is specifically about the HTTP/SSE code path - the same transport class covered in broader [Model Context Protocol security](https://anomity.ai/blog/model-context-protocol-mcp-security-explained/) guidance and in sibling unauthenticated MCP takes such as [Windows MCP unauthenticated PowerShell RCE](https://anomity.ai/blog/windows-mcp-unauthenticated-powershell-rce-ghsa-vrxg-gm77-7q5g/) and [Weknora unauthenticated MCP RCE](https://anomity.ai/blog/weknora-unauthenticated-mcp-rce-cve-2026-30861/).

## Fix and residual risk

- Upgrade to mysql-mcp-server 0.4.2 or later - the fixed release restores DNS-rebinding protection and related host allowlisting.
- Do not run SSE unless you need it - prefer stdio for local agent wiring when HTTP is not required.
- Bind loopback and front with an authenticated reverse proxy if SSE must stay on; the advisory class still warns that transport alone is not a full auth story.
- Least-privilege MySQL credentials for the MCP process so a remaining misconfig cannot dump production schemas.
- Inventory who enabled MCP_TRANSPORT=sse - environment flags on developer machines rarely appear in a CMDB.

This finding pairs with the same week's [GitLab MCP streamable HTTP DNS rebinding](https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/) and the pattern write-up on [why local MCP HTTP keeps falling to DNS rebinding](https://anomity.ai/blog/mcp-local-http-dns-rebinding-class-2026/). SDK knobs exist; package authors keep shipping without enabling them.

## How Anomity surfaces exposed MCP HTTP

Patching **0.4.2** closes this CVE. The durable control is still knowing **which MCP URLs and transports run where**, and denying unsafe tool calls before they execute.

Anomity's **Endpoint Sensor** inventories MCP servers among the eight AI artifact types on each managed endpoint, so an unexpected SSE listener is a fleet query. **Browser Sensor** and **cloud discovery** (Google Workspace / GitHub OAuth grants) cover adjacent AI surfaces. On agents with a hook such as Claude Code **PreToolUse**, [runtime governance](https://anomity.ai/#runtime-governance) returns **allow, deny, or log** before a call runs. Every decision lands in a [queryable 90-day audit trail](https://anomity.ai/#outcomes) and can route to SIEM, Slack, email, or Jira. Anomity is SOC 2 Type II and complements Network, EDR, DLP, and GRC.

**CVE-2026-59971** is what happens when MCP HTTP is treated as a convenience flag. Upgrade to **0.4.2**, inventory SSE listeners, and [book a 30-minute demo](https://anomity.ai/#early-access) to see which MCP transports your fleet actually exposed.

Share: Copied

## Frequently asked questions

Am I affected by CVE-2026-59971?
You are in scope if any host runs the PyPI package mysql-mcp-server before 0.4.2 with MCP_TRANSPORT=sse. Stdio-only deployments of the same package are outside this CVE. Confirm the installed version on developer and server endpoints, and whether SSE was enabled via environment or config rather than assumed from the README default.

What failed in the SSE transport?
SseServerTransport was created without security_settings, which disabled the MCP Python SDK Origin and Host checks that exist specifically to stop DNS rebinding. Combined with a default bind to 0.0.0.0, missing CORS/TrustedHost middleware, and no route authentication, a browser-origin or network attacker who can reach the listener can drive MCP traffic - including SQL-capable tools - without credentials.

Why is CVSS 10.0 for a local MCP package?
The published vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Network-reachable, unauthenticated SQL against a production database is a full confidentiality, integrity, and availability hit with scope change. Loopback-only mental models do not apply when the process binds all interfaces and skips Host/Origin validation.

Is upgrading to 0.4.2 enough?
It is the required fix for this CVE: 0.4.2 turns DNS-rebinding protection back on and documents MCP_SSE_ALLOWED_HOSTS. SSE still needs deployment hygiene - prefer loopback bind, authenticated reverse proxy, and least-privilege MySQL credentials - because transport hardening is not the same as application authentication for every exposure model.

How does Anomity help with exposed MCP HTTP listeners?
Anomity's Endpoint Sensor inventories MCP servers among the AI artifacts on each managed endpoint, so SSE and HTTP listeners become a fleet query rather than a rumor. On agents that expose a hook such as Claude Code PreToolUse, Anomity returns allow, deny, or log before a tools/call runs. Decisions land in a queryable 90-day audit trail and can route to SIEM, Slack, email, or Jira. Metadata only; secrets are redacted on-endpoint. That complements Network, EDR, DLP, and GRC.

## Related

[Advisory Critical ### mcp-atlassian HTTP Auth Bypass Falls Back to Global Credentials - CVE-2026-77254 CVE-2026-77254 (CVSS 9.1): unauthenticated HTTP MCP requests to mcp-atlassian below 0.22.0 fall through to globally configured Jira/Confluence credentials. Sibling CVE-2026-77244 (CVSS 10.0) accepts any non-empty token. Anomity Research · Sep 28, 2026 · CVE-2026-77254 (CVSS 9.1, GHSA-vc8m-84rp-53hx); sibling CVE-2026-77244 (CVSS 10.0, GHSA-wrhw-j3f9-8vc6)](https://anomity.ai/blog/mcp-atlassian-http-auth-bypass-global-credentials-cve-2026-77254/)

[Advisory Critical ### GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost CVE-2026-61568 (CVSS 9.6): @zereight/mcp-gitlab Streamable HTTP skipped SDK DNS-rebinding Host/Origin allowlists on loopback - fixed in 2.1.30. Anomity Research · Sep 21, 2026 · CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7)](https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/)

[Advisory High ### LiteLLM MCP Auth Bypass CVE-2026-59822 Lands in CISA KEV CVE-2026-59822 (CVSS 8.2, GHSA-7488-6r32-c95q): LiteLLM MCP Streamable HTTP OAuth2 passthrough yielded empty UserAPIKeyAuth. Fixed in 1.84.0; CISA KEV deadline 2026-09-16. Anomity Research · Sep 14, 2026 · CVE-2026-59822 (CVSS 8.2, GHSA-7488-6r32-c95q)](https://anomity.ai/blog/litellm-mcp-oauth-passthrough-auth-bypass-cve-2026-59822/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding",
  "description": "CVE-2026-59971 (CVSS 10.0): mysql-mcp-server SSE mode skipped Host/Origin DNS-rebinding protection, bound 0.0.0.0 with no auth - unauthenticated SQL until 0.4.2.",
  "datePublished": "2026-09-21",
  "dateModified": "2026-09-21",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/prompt-injection.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "MCP Server Security",
  "url": "https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/",
  "keywords": "MySQL MCP Server CVE-2026-59971 DNS rebinding, CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2), CVE-2026-59971, GHSA-rqfv-2mw9-78g2, mysql-mcp-server, MCP, SSE, DNS rebinding, Origin validation, unauthenticated SQL, agentic AI security"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Am I affected by CVE-2026-59971?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "You are in scope if any host runs the PyPI package mysql-mcp-server before 0.4.2 with MCP_TRANSPORT=sse. Stdio-only deployments of the same package are outside this CVE. Confirm the installed version on developer and server endpoints, and whether SSE was enabled via environment or config rather than assumed from the README default."
      }
    },
    {
      "@type": "Question",
      "name": "What failed in the SSE transport?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "SseServerTransport was created without security_settings, which disabled the MCP Python SDK Origin and Host checks that exist specifically to stop DNS rebinding. Combined with a default bind to 0.0.0.0, missing CORS/TrustedHost middleware, and no route authentication, a browser-origin or network attacker who can reach the listener can drive MCP traffic - including SQL-capable tools - without credentials."
      }
    },
    {
      "@type": "Question",
      "name": "Why is CVSS 10.0 for a local MCP package?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The published vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Network-reachable, unauthenticated SQL against a production database is a full confidentiality, integrity, and availability hit with scope change. Loopback-only mental models do not apply when the process binds all interfaces and skips Host/Origin validation."
      }
    },
    {
      "@type": "Question",
      "name": "Is upgrading to 0.4.2 enough?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is the required fix for this CVE: 0.4.2 turns DNS-rebinding protection back on and documents MCP_SSE_ALLOWED_HOSTS. SSE still needs deployment hygiene - prefer loopback bind, authenticated reverse proxy, and least-privilege MySQL credentials - because transport hardening is not the same as application authentication for every exposure model."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help with exposed MCP HTTP listeners?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity's Endpoint Sensor inventories MCP servers among the AI artifacts on each managed endpoint, so SSE and HTTP listeners become a fleet query rather than a rumor. On agents that expose a hook such as Claude Code PreToolUse, Anomity returns allow, deny, or log before a tools/call runs. Decisions land in a queryable 90-day audit trail and can route to SIEM, Slack, email, or Jira. Metadata only; secrets are redacted on-endpoint. That complements Network, EDR, DLP, and GRC."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding",
      "item": "https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/"
    }
  ]
}
```
